> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getprimo.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Preview the issues the rule draft of a SaaS raises

> Judge the DRAFT of the provisioning rule of the given SaaS — the text the rule editor shows, published or not — against the whole directory, exactly as publishing it would: every employee compared to the account they hold, and every identity on the SaaS. Returns the persons it would flag, with the issues (missing or unexpected access, groups, roles, licenses and organization units to add or remove), and `compliantCount`, the employees it leaves in order. Same issue types as `getSaasIssues`, which lists what the published rule found.

It creates and stores nothing, and works whatever the approval status of the SaaS. It reads the saved draft, never a text passed in: save it with `updateSaasRule` first. EXPENSIVE: one AI judgement over the whole directory — call it once per check, never in a loop.

<span className="badge-read">Key: Read</span><span className="badge-company">Scope: Company</span>


## OpenAPI

````yaml https://api.getprimo.com/openapi.json post /saas/{saasId}/issues/preview
openapi: 3.1.1
info:
  title: Public API - BETA
  description: Read docs on https://docs.getprimo.com/
  version: '1.0'
  contact: {}
servers:
  - url: https://api.getprimo.com
security:
  - apikey: []
tags: []
paths:
  /saas/{saasId}/issues/preview:
    post:
      tags:
        - Saas
      summary: Preview the issues the rule draft of a SaaS raises
      description: >-
        Judge the DRAFT of the provisioning rule of the given SaaS — the text
        the rule editor shows, published or not — against the whole directory,
        exactly as publishing it would: every employee compared to the account
        they hold, and every identity on the SaaS. Returns the persons it would
        flag, with the issues (missing or unexpected access, groups, roles,
        licenses and organization units to add or remove), and `compliantCount`,
        the employees it leaves in order. Same issue types as `getSaasIssues`,
        which lists what the published rule found.


        It creates and stores nothing, and works whatever the approval status of
        the SaaS. It reads the saved draft, never a text passed in: save it with
        `updateSaasRule` first. EXPENSIVE: one AI judgement over the whole
        directory — call it once per check, never in a loop.
      operationId: previewSaasIssues
      parameters:
        - name: saasId
          required: true
          in: path
          schema:
            type: string
      responses:
        default:
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/PreviewSaasIssues_Output'
components:
  schemas:
    PreviewSaasIssues_Output:
      type: object
      properties:
        compliantCount:
          type: integer
          description: Current employees the draft flags nothing for.
          minimum: -9007199254740991
          maximum: 9007199254740991
        data:
          type: array
          description: >-
            One entry per employee or identity the draft flags; compliant
            employees are left out.
          items:
            type: object
            properties:
              employeeId:
                description: >-
                  Employee the entry is about, or `null` for an orphaned
                  identity.
                anyOf:
                  - type: string
                  - type: 'null'
              name:
                description: Full name of the employee, else the email of the identity.
                anyOf:
                  - type: string
                  - type: 'null'
              issues:
                description: What the draft would flag for this person.
                type: array
                items:
                  type: object
                  properties:
                    type:
                      type: string
                      enum:
                        - NEED_ACCESS
                        - SHOULD_NOT_HAVE_ACCESS
                        - SHOULD_BE_MEMBER_OF_GROUP
                        - SHOULD_NOT_BE_MEMBER_OF_GROUP
                        - SHOULD_HAVE_ROLE
                        - SHOULD_NOT_HAVE_ROLE
                        - SHOULD_HAVE_LICENSE
                        - SHOULD_NOT_HAVE_LICENSE
                        - SHOULD_BE_IN_ORGANIZATION_UNIT
                        - ORPHANED_IDENTITY
                    identityId:
                      description: >-
                        Account of the person the issue is about, or `null` when
                        the person has no account on the SaaS.
                      anyOf:
                        - type: string
                        - type: 'null'
                    groupId:
                      description: Group involved in the issue, when applicable.
                      anyOf:
                        - type: string
                        - type: 'null'
                    roleId:
                      description: Role involved in the issue, when applicable.
                      anyOf:
                        - type: string
                        - type: 'null'
                    licenseId:
                      description: License involved in the issue, when applicable.
                      anyOf:
                        - type: string
                        - type: 'null'
                    organizationUnitId:
                      description: >-
                        Organization unit involved in the issue, when
                        applicable.
                      anyOf:
                        - type: string
                        - type: 'null'
                    resourceName:
                      description: >-
                        Name of the group, role, license or organization unit
                        involved, when applicable.
                      anyOf:
                        - type: string
                        - type: 'null'
                  required:
                    - type
                    - identityId
                    - groupId
                    - roleId
                    - licenseId
                    - organizationUnitId
                    - resourceName
                  additionalProperties: false
            required:
              - employeeId
              - name
              - issues
            additionalProperties: false
      required:
        - compliantCount
        - data
      additionalProperties: false
  securitySchemes:
    apikey:
      scheme: bearer
      bearerFormat: API key
      type: http
      description: >-
        Use your Primo API key in the Authorization header as `Bearer
        <API_KEY>`.

````